PT-2018-16989 · Netapp · Netapp 7-Mode Transition Tool
Publicado
2018-08-03
·
Atualizado
2019-10-03
·
CVE-2018-5489
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetApp 7-Mode Transition Tool versions prior to 2.0
Description
The issue allows users with valid credentials to access functions and information that may have been intended for administrators or privileged users. This occurs because versions prior to 2.0 do not enforce user authorization rules on file information and status that has been previously collected.
Recommendations
For versions prior to 2.0, update to version 2.0 or later, which maintains and verifies authorization rules for file information, status, and utilities.
Correção
Incorrect Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Netapp 7-Mode Transition Tool